ISC2 CC IN 2026
Is ISC2 CC Worth It in 2026, Now the Free Exam Has Ended?
Who the ISC2 Certified in Cybersecurity still suits after the One Million CC programme closed on 20 May 2026, what the 1 September 2026 outline changed, a 60-hour study budget and how to read CC questions.

The ISC2 Certified in Cybersecurity (CC) is still worth it in 2026 for one group of people: beginners with no security experience who need a credible first step into roles such as SOC analyst, junior security analyst or IT support with security duties. It is less worth it if you already have a few years in IT security or already hold a stronger credential. What changed this year is the cost: ISC2 closed its One Million Certified in Cybersecurity programme, which gave away the course and exam, to new sign-ups on 20 May 2026, so most new candidates now pay ISC2 for the exam. The exam itself also changed, with a new outline effective 1 September 2026.
Exam facts checked on ISC2's pages in October 2026. ISC2 changes outlines and terms, so check again before you book.
What happened to the free CC exam?
ISC2 launched One Million Certified in Cybersecurity to grow the entry-level workforce, offering the CC online course and exam at no charge. In an announcement on 22 April 2026, ISC2 said the programme would end on 20 May 2026, after more than a million enrolments, more than 570,000 people taking the course and more than 65,000 earning the CC.
The programme page sets the rules for anyone caught in the middle:
- New enrolments closed effective 20 May 2026.
- An exam code that has not expired must be used to schedule and sit the exam by 31 December 2026.
- An expired code cannot be reactivated, and no new free exam seats will be issued.
- Learners who enrolled before the cut-off keep course access while it lasts; finishing the course is not required to sit the exam.
If you hold an unexpired code, book now. Test centre slots fill up towards the end of a year, and a code that lapses is gone.
What the 2026 exam looks like
ISC2's CC exam outline page lists an outline effective 1 September 2026 with five domains:
| Domain | Weight |
|---|---|
| 1. Security Principles | 24% |
| 2. Security Governance | 17.3% |
| 3. Identity and Access Management (IAM) Concepts | 20% |
| 4. Networking and Cloud Security Concepts | 21.3% |
| 5. Security Operations and Incident Response | 17.3% |
The exam uses computerized adaptive testing (CAT) with 100 to 125 multiple choice and advanced items in two hours, and the passing grade is 700 out of 1000 points. ISC2 says foundational AI concepts are now integrated across all five domains rather than added as a sixth. In practice that means questions such as treating poisoned training data as an integrity threat, or managing an AI agent's account like any other identity.

Who the CC is worth it for
The CC certification page says no work experience is required and names IT professionals, career changers and students as its audience. That fits how hiring managers use it: as evidence that a candidate without experience knows the vocabulary and the basic ideas, and is serious enough to sit a proctored exam.
| Your situation | Is the CC worth it? | Why |
|---|---|---|
| Student or graduate aiming at a first security job | Usually yes | No experience needed; shows the basics on a CV |
| Career changer from another field | Usually yes | A structured way to learn the language of security |
| IT support or network technician | Often yes | Adds security vocabulary to existing skills |
| Holder of an unexpired One Million CC code | Yes, book now | The exam is already paid for until 31 December 2026 |
| Two or more years in a security role | Rarely | Your experience says more than an entry-level exam |
| Already planning a broader foundation exam | Maybe | Compare the outlines; one strong foundation may be enough |
The CC is also the bottom rung of ISC2's own ladder. People who go on to its associate and professional certifications often find that the CC vocabulary carries straight over. After passing, ISC2 has its own requirements for keeping the certification in good standing, so read them on isc2.org before you book.
What the CC will not do for you
Be honest about the limits before you spend money and weekends on it.
- It does not prove hands-on skill. The exam tests concepts. Employers still ask what you have built, configured or investigated.
- It does not replace networking knowledge. Domain 4 assumes you can read IP addresses, ports and the OSI model. If those are new, learn them first.
- It is not a specialist credential. Cloud security, SOC work and industrial control system security each have their own deeper paths.
How long does it take? Most beginners need four to eight weeks of steady study, depending on how much networking they already know and how many evenings they can give it. Someone who already works in IT support can often be ready in three or four weeks, because Domains 3 and 4 will feel familiar from daily work.
The strongest beginner profiles combine three things: a foundation certification such as the CC, a small home lab you can talk about in an interview, and one piece of work you can show, such as a write-up of a packet capture or an access review.
Worked example: a 60-hour study budget
Suppose you can give the CC 60 hours over six weeks. Split the time by the domain weights so effort follows the marks:
- Domain 1: 60 x 0.24 = 14.4 hours
- Domain 2: 60 x 0.173 = 10.38, so about 10.4 hours
- Domain 3: 60 x 0.20 = 12.0 hours
- Domain 4: 60 x 0.213 = 12.78, so about 12.8 hours
- Domain 5: 60 x 0.173 = 10.4 hours
Check: 14.4 + 10.4 + 12.0 + 12.8 + 10.4 = 60.0 hours. Then adjust for your background. A network technician might move four hours from Domain 4 to Domain 2, where governance terms such as RTO, RPO and maximum tolerable downtime are likely to be new.
A second check: one risk calculation. Domain 1 expects simple quantitative risk. A server valued at 80,000 (any currency) would lose 40 percent of its value in a ransomware attack expected once every four years. The single loss expectancy is 80,000 x 0.40 = 32,000, and the annualised loss expectancy is 32,000 x 0.25 = 8,000 a year. A control costing 3,000 a year that cuts the rate to once in 20 years gives an ALE of 32,000 x 0.05 = 1,600, a saving of 6,400 against a cost of 3,000. The control is worth it by 3,400 a year. If that reasoning feels comfortable, Domain 1 will too.
How to read CC questions
Most wrong answers in a CC question are plausible actions, just not the best one for the role described. A four-step method helps:
- Role: you are usually an entry-level practitioner who follows policy and escalates.
- Goal: what must be protected or achieved in the scenario.
- Qualifier: FIRST, BEST, MOST, LEAST or NOT changes the answer.
- Best answer: of the options that are true, choose the one a manager would expect from that role.
Because the exam is adaptive, its length varies between 100 and 125 items and it stops once it is confident of the result. Pace yourself at about a minute an item.

Never use exam dumps
Sites that sell "real CC exam questions" break ISC2's exam rules, and candidates caught using them can lose the certification. Adaptive testing also makes memorised items unreliable. Use original practice questions written to the published outline, and read the explanation for every answer you get wrong. If you are moving towards plants and control systems later, our guide to OT cybersecurity and IEC 62443 shows how the same principles apply there.
A free way to prepare
The free ISC2 Certified in Cybersecurity (CC) Exam Prep course follows the five domains of the 1 September 2026 outline in twelve teaching modules, with lessons from ThorTeaches.com, IBM Technology and other educators, original notes and worked problems, and 148 original practice questions. Learning is free, so it costs you nothing to find out whether the CC is for you before you pay ISC2 for the exam.
It is a free course with a verifiable certificate of completion, and anyone can check a certificate on our verification page; our guide on how to verify an engineering training certificate explains what such a check shows. It is preparation only: ISC2, CC and Certified in Cybersecurity are ISC2's marks, EDWartens is not affiliated with ISC2, and the CC is earned only by passing ISC2's exam. Start the ISC2 CC exam prep course and decide with real practice scores in hand.
Take the free course
Questions
Is the ISC2 CC worth it in 2026?
Yes, for beginners with no security experience who want a first credential for roles such as SOC analyst or junior security analyst. It is less useful if you already have two or more years in security, because your experience and a more advanced credential will say more.
Is the ISC2 CC exam still free?
Not for new candidates. ISC2 closed its One Million Certified in Cybersecurity programme to new enrolments on 20 May 2026. Anyone holding an unexpired exam code from it must schedule and sit the exam by 31 December 2026; everyone else buys the exam from ISC2.
What changed in the CC exam on 1 September 2026?
A new outline took effect with five domains: Security Principles (24%), Security Governance (17.3%), IAM Concepts (20%), Networking and Cloud Security Concepts (21.3%) and Security Operations and Incident Response (17.3%). ISC2 also integrated foundational AI concepts across all five domains.
How hard is the ISC2 CC exam?
It is an entry-level exam, but it is adaptive, with 100 to 125 items in two hours and a passing grade of 700 out of 1000. Most beginners need four to eight weeks of steady study and plenty of scenario practice.
Do I need experience for the ISC2 CC?
No. ISC2 states that no work experience is required for the Certified in Cybersecurity, which is why students, career changers and IT staff moving into security take it as a first step.
Is there a free ISC2 CC prep course with a certificate?
Yes. ISC2 Certified in Cybersecurity (CC) Exam Prep on EDWartens is a free course with a verifiable certificate of completion, mapped to the 2026 outline with 148 original practice questions. It is not the ISC2 certification, which only ISC2 awards after its exam.
Sources
- ISC2: CC Certification Exam Outline, effective 1 September 2026 (read 11 October 2026)
- ISC2: One Million Certified in Cybersecurity programme page (read 11 October 2026)
- ISC2 Insights: conclusion of One Million Certified in Cybersecurity, 22 April 2026 (read 11 October 2026)
- ISC2: Certified in Cybersecurity (CC) certification page (read 11 October 2026)
Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.

1Z0-1122 Study Guide: OCI AI Foundations, Topic by Topic

Wazuh vs Splunk: Which SIEM to Learn and Run in 2026

ISO 27001 Annex A Controls Explained: All 93 by Theme

Subnetting Explained for PLC and OT Networks, With a Free CCNA Video Lesson

Controls Engineer Certifications: CAP, CCST and More

Do Online Courses Count as CPD or PDH for Engineers?


